First published: Tue Mar 08 2022(Updated: )
.NET and Visual Studio Denial of Service Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET 5.0 | ||
Microsoft Visual Studio 2019 (includes 16.0 - 16.8) | =16.9 | |
Microsoft Visual Studio 2019 (includes 16.0 – 16.6) | =16.7 | |
Microsoft .NET Core | =3.1 | |
Microsoft Visual Studio 2019 (includes 16.0 - 16.10) | =16.11 | |
Microsoft Visual Studio 2022 | =17.0 | |
Microsoft .NET | >=5.0<=5.0.14 | |
Microsoft .NET | >=6.0.0<=6.0.2 | |
Microsoft .NET Core | >=3.1<=3.1.22 | |
Microsoft Visual Studio 2019 | >=16.0<=16.6.4 | |
Microsoft Visual Studio 2019 | >=16.7.0<16.7.26 | |
Microsoft Visual Studio 2019 | >=16.8.0<=16.8.7 | |
Microsoft Visual Studio 2019 | >=16.9.0<16.9.18 | |
Microsoft Visual Studio 2019 | >=16.10.0<=16.10.4 | |
Microsoft Visual Studio 2019 | >=16.11.0<16.11.11 | |
Microsoft Visual Studio 2022 | >=17.0.0<17.0.7 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Microsoft .NET 6.0 | ||
Microsoft Visual Studio 2022 | >=17.0<17.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24464 is a denial of service vulnerability in .NET and Visual Studio.
CVE-2022-24464 affects Microsoft .NET versions 5.0.0 to 5.0.14, 6.0.0 to 6.0.2, Microsoft .NET Core version 3.1.0 to 3.1.22, and Microsoft Visual Studio 2019 versions 16.0 to 16.11.11, and 17.0.0 to 17.0.7.
The severity of CVE-2022-24464 is high with a CVSS score of 7.5.
To fix CVE-2022-24464, you should update your software to the latest versions. Microsoft has provided patches and remediation steps, which can be found in the provided links in the references.
You can find more information about CVE-2022-24464 on the Microsoft Security Response Center website. The reference link provides additional details.